Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2009-1384 - CERT CVE
CVE-2009-1384
ID
CVE-2009-1384
Sažetak
pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Reference
http://osvdb.org/54791
http://secunia.com/advisories/35230
http://secunia.com/advisories/43314
http://www.mandriva.com/security/advisories?name=MDVSA-2010:054
http://www.openwall.com/lists/oss-security/2009/05/27/1
http://www.securityfocus.com/archive/1/516397/100/0/threaded
http://www.securityfocus.com/bid/35112
http://www.vmware.com/security/advisories/VMSA-2011-0003.html
http://www.vupen.com/english/advisories/2009/1448
https://bugzilla.redhat.com/show_bug.cgi?id=502602
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7081
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9652
CVSS
Base:
5.0
Impact:
2.9
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
PARTIAL
NONE
NONE
CVSS vektor
AV:N/AC:L/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje
10-10-2018 - 19:36
Objavljeno
28-05-2009 - 20:30